The South Australian (SA) Government has developed the SA Cyber Security Operating Model (the Operating Model) to ensure that the people, processes and systems are in place to prevent, detect and respond to cyber threats.

The Operating Model provides the bridge between strategy and day to day operations, by defining what we are doing and how we are doing it. It clarifies services, processes and activities to appropriately manage cyber security risk across the SA Government. It also defines the roles and responsibilities of the Office of the Chief Information Officer (OCIO) and SA Government agencies, and introduces a standardised cyber security taxonomy - aligned to the SA Cyber Security Framework (SACSF) - outlining what comprises cyber security responsibilities within government so agencies can apply that within their areas of responsibility.

The Operating Model reduces duplicated effort and creates opportunities of scale through the clear definition of centralised services, and improves consistency and efficiency through standardised approaches.

It also offers opportunities for greater allocation of resources to areas of highest risk through the identification of information assets of state significance.

The SA Cyber Security Operating Model includes architecture, design principles and a decision tree, commercial principles, a taxonomy, services and a RACI.

Commercial and Operational principles

The Operating Model's commercial and operational principles drive whole of government cost efficiencies associated with managing cyber security.

Centralised or standardised services are used by default where available - where provided, centralised or standardised services are used by default.

Funding of ongoing operational costs is considered - where a new central services capability is created, ongoing operational costs need to be considered at a whole of government level.

A streamlined service delivery model for central services is defined and communicated - central services should define a streamlined service delivery model to increase services uptake and enhance efficient delivery of services.

Operating Model Architecture

The Operating Model architecture clearly defines roles and responsibilities. The key architecture elements are:

OCIO Core - sets the whole of government cyber strategy and statewide cyber security requirements, drives whole of government leadership and collaboration, establishes overarching approaches and drives effectiveness in across-government cyber security risk management.

Central Services - services that provide better efficiencies of scale, scope or standardisation to provide more effective whole of government cyber security risk management.

Local Services - activities that require understanding of local context, local requirements and local subject matter. Local services are provided by either

  • Cluster agencies: large agencies with the capacity and capability (including sector understanding) to deliver local services to small agencies who have insufficient capacity and capability.
  • Standalone agency: agencies of sufficient capability and capacity to deliver local services. The Operating Model architecture shows the relationship between roles, describes the responsibilities of each role, and demonstrates the intersection of cyber security strategy, the Operating Model and cyber security operations between OCIO and agencies.

Cyber Security Taxonomy and RACI

The Cyber Security Taxonomy is organised into 14 key domains and associated activities. It describes what comprises cyber security services across the SA Government and is aligned to the SACSF.

The Cyber Security Operating Model RACI details the implementation responsibilities between OCIO and agencies for taxonomy activities, and can be used by agencies to assess their implementation of the Operating Model requirements.

Cyber Security Services

OCIO provides a range of cyber security services delivered across three roles described in the Operating Model: Core, Central Services and Local Services. They align to the whole of government Cyber Security Taxonomy and design principles.

SA Government agencies can access further information in the OCIO Service Catalogue under ‘Cyber security and risk services’.

Cyber Security Workforce Guide

To support agencies in implementing their responsibilities under the Operating Model, the Cyber Security Workforce Guide provides guidance on the cyber security workforce capabilities, roles and skills needed across government.

Authority

The Operating Model is a Cabinet-approved document. The Premier and Cabinet Circular PC004 ICT Digital and Cyber Security Requirements outlines the authority for OCIO to provide whole of government ICT, digital and cyber security services. It also requires agencies to consume services from the OCIO Service Catalogue before considering standalone solutions.

Governance

To ensure the benefits of the Operating Model are realised, effective governance oversight of the design, operating and commercial principles will be carried out using existing governance arrangements in the South Australian Government ICT, Digital and Cyber Security Governance Framework. These include the:

  • Cyber Security Advisory Group
  • Architecture Review Group
  • Chief Information Officer Steering Committee
  • Senior Leadership Committee

Other mechanisms with governance oversight of the Operating Model include the:

  • Cabinet Submission costing comment review process
  • Digital Investment Fund Board and Advisory Group

This will ensure future cyber security services are delivered by appropriate entities in accordance with the Operating Model, reducing duplicated effort and creating opportunities of scale through centralised services and standardised approaches.

To achieve the governance objectives, the Operating Model provides a Design Principles Decision Tree to determine cyber security service role location.